Financial Services
A surprising occurrence is happening in the consumer credit markets. Bank card issuers are back in acquisition mode, enticing consumers with cash back, airline points and other incentives to get a share of their wallet. And while new account originations are nowhere near the levels seen in 2007, recent growth in new bank card accounts has been significant; 17.6% in Q1 2011 when compared to Q1 2010. So what is accounting for this resurgence in the credit card space while the economy is still trying to find its footing and credit is supposedly still difficult to come by for the average consumer? Whether good or bad, the economic crisis over the past few years appears to have improved consumers debt management behavior and card issuers have taken notice. Delinquency rates on bank cards are lower than at any time over the past five years and when compared to the start of 2009 when bank card delinquency was peaking; current performance has improved by over 40%. These figures have given bank card issuers the confidence to ease their underwriting standards and re-establish their acquisition strategies. What’s interesting however is the consumer segments that are driving this new growth. When analyzed by VantageScore, new credit card accounts are growing the fastest in the VantageScore D and F tiers with 46% and 53% increases year over year respectively. For comparison, VantageScore A and B tiers saw 5% and 1% increases during the same time period respectively. And although VantageScore D and F represent less than 10% of new bank card origination volume ($ limits), it is still surprising to see such a disparity in growth rates between the risk categories. While this is a clear indication that card issuers are making credit more readily available for all consumer segments, it will be interesting to see if the debt management lessons learned over the past few years will stick and delinquency rates will continue to remain low. If these growth rates are any indication, the card issuers are counting on it.
By: Staci Baker The Durbin Amendment, according to Wikipedia, gave the Federal Reserve the power to regulate debit card interchange fees. The amendment, which will have a profound impact on banks, merchants and anyone who holds a debit card will take effect on October 1, 2011 rather than the originally announced July 21, 2011, which will allow banks additional time to implement the new regulations. The Durbin Amendment states that card networks, such as Visa and Mastercard, will include an interchange fee of 21 cents per transaction, and must allow debit cards to be processed on at least two independent networks. This will cost banks roughly $9.4 billion annually according to CardHub.com. As stipulated in the Amendment, institutions with less than $10 billion in assets are exempt from the cap. In preparation for the Durbin Amendment, several banks have begun to impose new fees on checking accounts, end reward programs, raise minimum balance requirements and have threatened to cap transaction amounts for debit card transactions at $50 to $100 in order to recoup some of the earnings they are expected to lose. These new regulations will be a blow to already hurting consumers as their out of wallet expenses keep increasing. As you can see, The Durbin Amendment, which is meant to help consumers, will instead have the cost from the loss of interchange fees passed along in other forms. And, the loss of revenue will greatly impact the bottom line of banking institutions. Who will be the bigger winner with this new amendment - the consumer, merchants or the banks? Will banks be able to lower the cost of credit to an amount that will entice consumers away from their debit cards and to use their credit cards again? I think it is still far too soon to tell. But, I think over the next few months, we will see consumers use payment methods in a new way as both consumers and banks come to a middle ground that will minimize risk levels for all parties. Consumers will still need to shop and bankers will still need their tools utilized. What are you doing to prepare for The Durbin Amendment?
Every communication company wants to inoculate its portfolio against bad debt, late payments and painful collections. But many still use traditional generic risk models to uncover potential problems, either because they’ve always used generics or because they see their limited predictive abilities as adequate enough. Generalization dilutes results The main problem with generics, however, is how they generalize consumers’ payment behavior and delinquencies across credit cards, mortgages, auto loans and other products. They do not include payment and behavioral data focused on actual communications customers only. Moreover, their scoring methodologies can be too broad to provide the performance, lift or behavioral insights today’s providers strive to attain. Advantages of industry-specific models Communications-specific modeling can be more predictive, if you want to know who’s more likely to prioritize their phone bill and remit promptly, and who’s not. In multiple market validations, pitting an optimized industry-specific model against traditional generic products, Experian’s Tele-Risk ModelSM and Telecommunications, Energy and Cable (TEC) Risk ModelSM more accurately predicted the likelihood of future serious delinquent or derogatory payment behavior. Compared with generics, they also: Provided a stronger separation of good and bad accounts More precisely classified good vs. bad risk through improved rank ordering Accurately scored more consumers than a generic score that might have otherwise been considered unscorable Anatomy of a risk score These industry risk models are built and optimized using TEC-specific data elements and sample populations, which makes them measurably more predictive for evaluating new or existing communications customers. Optimization also helps identify other potentially troublesome segments, including those that might require special handling during on boarding, “turn ons,” or managing delinquency. Check the vital signs To assess the health of your portfolio, ask a few simple questions: Does your risk model reflect unique behaviors of actual communications customers? Is overly generic data suppressing lift and masking hidden risk? Could you score more files that are currently deemed unscorable? Unless the answer is ‘yes’ to all, your model probably needs a check-up—stat.
Lately there has been a lot of press about breaches and hacking of user credentials. I thought it might be a good time to pause and distinguish between authentication credentials and identity elements. Identity elements are generally those bits of meta data related to an individual. Things like: name, address, date of birth, Social Security Number, height, eye color, etc. Identity elements are typically used as one part of the authentication process to verify an individual’s identity. Credentials are typically the keys to a system that are granted after someone’s identity elements have been authenticated. Credentials then stand in place of the identity elements and are used to access systems. When credentials are compromised, there is risk of account takeover by fraudsters with mal intent. That’s why it’s a good idea to layer-in risk based authentication techniques along with credential access for all businesses. But for financial institutions, the case is clear: a multi-layered approach is a necessity. You only need to review the FFIEC Guidance of Authentication in an Internet Banking Environment to confirm this fact. Boiled down to its essence, the latest guidance issued by the FFIEC is rather simple. Essentially it’s asking U.S. financial institutions to mitigate risk using a variety of processes and technologies, employed in a layered approach. More specifically, it asks those businesses to move beyond simple device identification — such as IP address checks, static cookies and challenge questions derived from customer enrollment information — to more complex device intelligence and more complex out-of-wallet identity verification procedures. In the world of online security, experience is critical. Layered together, Experian’s authentication capabilities (including device intelligence from 41st Parameter, out-of-wallet questions and analytics) offers a more comprehensive approach to meeting and exceeding the FFIEC’s most recent guidance. More importantly, they offer the most effective and efficient means to mitigating risk in online environments, ensuring a positive customer experience and have been market-tested in the most challenging financial services applications.
By: Kennis Wong On the surface, it’s not difficult to define existing account fraud. Obviously, it is fraud perpetrated against an existing account. But the way I see it, existing account fraud can be broken down into four types. The first type is account takeover fraud, which is what most organizations think as the de facto existing account fraud. This is when a real consumer using his or her own identity to open a legitimate account, but the account later on get taken over by an identity fraudster. The idea is that when the account was first established, it was created by the rightful person. But somewhere along the way, the account and identity information were compromised. The fraudster uses the compromised information to engineer their way into the account. The second type is impersonation. Impersonation is somewhat similar to account takeover in the sense that it is also misusing the victim’s account. But the difference is that impersonation is more of a one or few times misuses of the account. Examples are a fraudulent use of a credit card or wire transfer. These are the obvious categories. But I think we should also think about these other categories. My definition of existing account fraud also includes this third type – identity fraud that was undetected during application. In other words, an account is established based on stolen identity. Many organizations call this “new account fraud”, which I don’t have a problem with. But I think it’s really also existing account fraud, because – is this existing account? The answer is yes. Is this fraud? Absolutely. It’s not that difficult, is it? Similarly, I am including first-party fraud in existing account fraud as well. A consumer can use his or her own identity to open an account, with an intention to default after the account is established. Example is bust out fraud. You see that this is an expanded definition of existing account fraud, because my focus is on detection. No matter at what point and how identity fraud comes in, it becomes an account in your organization, and that is where we need to discover the fraud. But at the end of the day, it’s not too important how to categorize or name the fraud - whether it's application fraud, existing account fraud, first party fraud or third party fraud, as long as organizations understand them enough and have a good way to detect them. Read more blog posts on existing account fraud.
By: Kari Michel The topic of strategic default has been a hot topic for the media as far back as 2009 and continues as this problem won’t really go away until home prices climb and stay there. Terry Stockman (not his real name) earns a handsome income, maintains a high credit score and owns several residential properties. They include the Southern California home where he has lived since 2007. Terry is now angling to buy the foreclosed home across the street. What’s so unusual about this? Terry hasn’t made a mortgage payment on his own home for more than six months. With prices now at 2003 levels, his house is worth only about one-half of what he paid for it. Although he isn’t paying his mortgage loan, Terry is current with his other debt payments. Terry is a strategic defaulter — and he isn’t alone. By the end of 2008, a record 1 in 5 mortgages at least 60 days past due was a strategic default. Since 2008, strategic defaults have fallen below that percentage in every quarter through the second quarter of 2010, the most recent quarter for which figures are available. However, the percentages are still high: 16% in the last quarter of 2009 and 17% in the second quarter of last year. Get more details off of our 2011 Strategic Default Report What does this mean for lenders? Mortgage lenders need to be able to identify strategic defaulters in order to best employ their resources and set different strategies for consumers who have defaulted on their loans. Specifically designed indicators help lenders identify suspected strategic default behavior as early as possible and can be used to prioritize account management or collections workflow queues for better treatment strategies. They also can be used in prospecting and account acquisition strategies to better understand payment behavior prior to extending an offer. Here is a white paper I thought you might find helpful.
When the Consumer Financial Protection Bureau (CFPB) takes authority on July 21, debt collectors and communications companies should pay close attention. If the CFPB has its way, the rules may be changing. Old laws, new technologies The rules governing consumer communications for debt collection haven’t seen a major update since they were written in 1977. While the FTC has enforcement power in this area, it can’t write rules—Congress must provide direction. Consequently, the rules guiding the debt collection industry have evolved based on decisions by the courts. In the meantime, technology has outpaced the law. Debt collectors have taken advantage of the latest available methods of communication, such as cell phones, autodialers and email, while the compliance requirements have largely remained murky. At the same time, complaints about debt collection practices to the FTC continue to rise. While the number is relatively low compared to the amount of overall activity, the FTC receives more complaints about debt collectors than any other industry. The agency has also raised concerns about how new communication tools, such as Facebook and Twitter, will impact the future of debt collection. Priorities for the CFPB While mortgages, credit cards and payday loans will be the early priorities for the CFPB, high on the list of to-do items will be to update the laws governing consumer communications for debt collection. Under the Dodd-Frank Act, the CFPB will be responsible not only for enforcing the Fair Debt Collection Practices Act (FDCPA), but it will also have a new ability to write the rules. This raises new issues, such as how new regulations will affect how debt collection companies can contact consumers. Even as lenders and communications companies have expressed concern about the CFPB writing the rules, the hope is that the agency will create a more predictable legal structure that covers new technologies and reduces the uncertainty around compliance. Faced with the prospect of clarifying the compliance requirements around debt collection, the ACA (Association of Collection and Credit Professionals) has started to get in front of the CFPB by putting together its own blueprint. Will the CFPB be ready by July 21? Over the last year, the CFPB has been busy building an organizational structure but still lacks a leader appointed by the President and confirmed by the Senate. (Elizabeth Warren is currently the unofficial director.) Without a permanent director in place, the agency will be unable to gain full regulatory authority on July 21 – the date set by the Treasury Department. Until then, the CFPB will be able to enforce existing laws but will be unable to write new regulations. Despite the political uncertainty, debt collectors and communications firms still need to be prepared. One way is to ensure you’re following industry best practices established by ACA. To help you be ready for any outcome, we’ll continue to follow this issue and keep you apprised of the CFPB’s direction. Let us know your thoughts and concerns in the comment section. Or feel free to contact your Experian rep directly with any questions you may have. Helpful links: Association of Credit and Collection Professionals Fair Debt Collection Practices Act (PDF) Consumer Financial Protection Bureau (CFPB)
The Communications Fraud Control Association’s annual meeting and educational event was held last week (June 14 – 16) at the Allerton hotel in Chicago, IL. The Communications Fraud Control Association is made up of communications and security professionals, fraud investigators, analysts, and managers, law enforcement, those in risk management, and many others. As an organization, they started out as a small group of communications professionals from the major long distance carriers who were looking for a better and more collaborative way to address communications fraud. Now, almost 30 years later, they’ve got over 60 members – a great representation of the industry yet still a nimble size. From what I hear, this makes for a specialized but quite effective “working” conference. Unfortunately I was not able to attend the conference but my colleague, Kennis Wong, attended and presented on the topic of Account Takeover and existing account fraud. It’s an area of fraud and compliance that Experian has spent some R&D on recently, with some interesting findings. In the past, we’ve been more focused on helping clients prevent new account and application fraud. It might seem like an interesting time to expand into this area, with some studies citing large drops in existing account fraud (2011 Identity Fraud Survey Report by Javelin). BUT...consumer costs in this area are way UP, not to mention the headline-grabbing news stories about small business account takeover. Which means it’s still a large pain point for financial institutions. Experian’s research and development in existing account fraud, combined with our expertise in fraud scores and identity theft detection, has resulted in a new product which is launching at the end of this month: Precise ID for Customer Management. Stay tuned for more exciting details.
Whether you call it small business, commercial, or corporate account takeover, this form of existing account fraud has been in the headlines lately and seems to be on the rise. While account takeover happens to individual consumers quite frequently, it’s the sensational loss amounts and the legal battles between companies and their banks that are causing this form of commercial fraud to make the news. A recent BankInfoSecurity.com article, Fraud Verdict: Opinions Vary, is about a court opinion on a high profile ACH fraud case - Experi-Metal Inc. vs. Comerica Bank – that cites a number of examples of corporate account takeover cases with substantial losses: · Village View Escrow of Redondo Beach, Calif.: lost $465,000 to an online hack · Hillary Machinery: settled with its bank for undisclosed terms in 2010. · The Catholic Diocese of Des Moines, Iowa: lost $600,000 in fraudulent ACH transactions. I was curious what information was out there and publicly available to help businesses protect themselves and minimize fraud losses / risk. NACHA, the electronics payment association, had some of the best resources on their website. Labeled the “Corporate Account Takeover Resource Center”, it has a wide variety of briefs, papers, and recommendations documents including prevention practices for companies, financial institutions, and third-party service providers. There’s even a podcast on how to fight ACH fraud! One thing was interesting to note, though. NACHA makes a point to distinguish between ACH fraud and corporate account takeover in this statement at the top of the web page: Corporate Account Takeover is a form of corporate identity theft where a business’ online credentials are stolen by malware. Criminal entities can then initiate fraudulent banking activity. Corporate Account Takeover involves compromised identity credentials and is not about compromises to the wire system or ACH Network. ACH fraud and wire fraud, terms mistakenly used to describe this type of criminal activity, are a misnomer. The ACH Network is safe and secure. Mostly I agree –the ACH Network is safe and secure. But from an F.I.'s or company’s perspective, corporate account takeover and ACH Fraud often go hand in hand.
High-profile data breaches are back in the headlines as businesses—including many in the communications sector—fall prey to a growing number of cyberattacks. So far this year, 251 public notifications of data breaches have been reported according to the Privacy Rights Clearinghouse. The latest attack comes on the heels of the Obama administration’s recent proposal to replace conflicting state laws with a uniform standard. The idea is not a new one—national breach notification legislation has been in discussion on Capitol Hill since 2007. With the addition of the White House proposal, three data breach notification bills are now under consideration. But rather than waiting for passage of a new law, communications companies and businesses in general should be aware of the issues and take steps to prepare. Replacing 48 laws with one Currently, notification standards differ on a state-by-state basis: 46 states, plus the District of Columbia and Puerto Rico each enforce their own standards. The many varying laws make compliance confusing and expensive. While getting to a single standard sounds like a good idea, finding a single solution becomes difficult when there are 48 different laws to reconcile. The challenge is to craft a uniform national law that preempts state laws, while providing adequate consumer protection. Five things to look for in a National Breach Notification Law Passing a single law will be an uphill battle. In the meantime, these are some of the issues that will need to be resolved before a national breach standard can be enacted: What types of personal information should be protected? First and last name + other info (e.g. bank account number) What should be classified as “personal” information? Email addresses and user names Health and medical information (California now includes this) What qualifies as a breach and what are the triggers for notification? What information should be included in a breach notice? How soon after a breach should notification be sent? Some states require notices be sent within a set number of days, others ASAP. Potential penalties What could happen if a company doesn’t comply with the proposed laws? Under the White House bill, fines would be limited to $1,000/day, with a $1 million cap. The two bills in House would impose penalties of $11,000/day, maxing out at $5 million. How to prepare before a national standard is passed Although the timing for passage is uncertain, communications companies need not wait for a national law to pass before taking action. Put a plan in place instead of sorting through 48 different laws. Preparation can be as simple as making a phone call to your Experian rep about our data breach protection services. Having managed over 2,300 data breach events, Experian can help you effectively mitigate loss. In addition to following updates on this page, you can also stay informed about the progress of pending data breach legislation by following the Data Breach Blog. Share your thoughts and concerns on the current proposals by leaving a comment. For further reading on this subject: Experian Data Breach Blog State Security Breach Notification Laws Obama Administration Proposal: Law Enforcement Provisions Related to Computer Security (pdf of the full bill) Obama national breach notification proposal: Good news, bad news for firms 2011 Data Breach Investigations Report (PDF)
For communications companies, acquiring new accounts is an ongoing challenge. However, it is critical to remember that managing new and existing accounts – and their respective risks – is of tremendous importance. A holistic view of the entire customer lifecycle is something every communications organization can benefit from. The following article was originally posted by Mike Myers on the Experian Business Credit blog. Most of us are pretty familiar with credit reports and scores, but how many of you are aware of the additional tools available to help you manage the entire credit risk lifecycle? I talk to credit managers everyday and as we’re all trying to do more with less, it’s easy to forget that opening accounts is just the first step. Managing risk on these accounts is as critical, if not more so, than opening them. While others may choose to “ship and chase”, you don’t need to. Proactive alert/monitoring services, regular portfolio scoring and segmentation are key components that a successful credit department needs to employ in the constant battle against “bad” accounts. Use these tools to proactively adjust credit terms and limits, both positively and negatively. Inevitably some accounts will go bad, but using collection research tools for skip tracing and targeting services for debt collection will put you first in line for collections. A journey of 1,000 miles begins with a single step; we have tools that can help you with that journey and all can be accessed online.
At Experian’s recent client conference, Vision 2011, there was a refreshing amount of positive discussion and outlook on origination rates and acquisition strategies for growth. This was coming not only from industry analysts participating in the conference but from clients as well. As a consumer, I’d sensed the ‘cautious optimism’ that we keep hearing about because my mailbox(the ‘original’ one, not email) has slowly been getting more and more credit card offer letters over the last 6 months. Does this mean a return to prospecting and ultimately growth for financial institutions and lenders? It’s a glimmer of hope, for sure, although most agree that we’re a long way from being out of the woods, particularly with unemployment rates still high and the housing market in dire shape. Soooo…..you may be wondering where I’m going with this…. Since my job is to support banks, lenders, utilities and numerous other businesses’ in their fraud prevention and compliance efforts, where my mind goes is: how does a return to growth – even slight – impact fraud trends and our clients’ risk management policies? While many factors remain to be seen, here are a few early observations: · Account takeover, bust out fraud, and other types of existing account fraud had been on the rise while application fraud had declined or stayed the same (relative to the decrease in new originations); with prospecting and acquisition activity starting to increase, we will likely see a resurgence in new account fraud attempts and methods. · Financial institutions and consumers are under increasing risk of malware attacks; with more sophisticated malware technology popping up every day, this will likely be a prime means for fraudsters to commit identity theft and exploit potentially easier new account opening policies. · With fraud loss numbers flat or down, the contracted fraud budgets and delayed technology investments by companies over the last few years are a point of vulnerability, especially if the acquisition growth rate jumps substantially.
The end of 2010 was a transitional time for credit card lenders. Card issuers were faced with the need to jump-start “return to growth strategies” as a result of diminished profits stemming from the great recession and all of the credit tightening actions deployed over the last two years. Lenders were deliberate in their actions to shrink balance sheets eliminating higher risk customers. At the same time, risk adverse consumers were, and continue to be, more thoughtful about spending, taking deliberate measures to buy what they perceive to be necessary and able to pay back. Being the only safe bet in town, the super prime universe went from saturated to abundantly over-saturated, and only recently have lenders begun to turn the ship in anticipation of continued relief in default trends. As a result of sustained relief in credit card defaults and over-saturation in the prime+ space, more lenders have begun loosening policies. This has created price competition with 74% of new offers including low introductory rates for longer durations, averaging 12 months, up from 9 months just one year ago. The percent of annual fee offers decreased as well to 21% from 34% one year prior. Continuing the trend of competing for the prime+ segment, lenders have increasingly been promoting loyalty programs, in many cases, combined with spend-incented rebates. In fact, over a third of new offers were for rewards based products, up from 26% prior to the start of the economic turn in 2007. Lenders are now shifting gears to compete in new ways focusing on consumer demand for payment choices. Regardless of a consumer’s credit profile, lenders and technology providers are investing in innovative payment solutions. Lenders understand that if the Starbucks “My Coffee Card” is only available on their customer’s iPhone, Blackberry or Android using a re-loadable Starbucks app, then traditional card issuers will lose purchase volume. What is becoming more and more critical is a lenders ability to leverage new data sources in their targeting strategies. It is no longer enough to know what products provide the most relevance to consumer needs. A lender must now know the optimal communication channel for unique segments of the population, their payment preferences and the product terms and features that competitively match the consumer’s needs and risk profile. Lenders are leveraging new data sources around income, wealth, rent payment, ARM reset timing and strategic default, wallet spend and purchase timing.Loading...
About a month ago, Senior Decisioning Consultant Krista Santucci and I gave a presentation at Experian’s 2011 Vision Conference on Decisioning as a Service. Due to the positive feedback we received, I thought it might be of interest to members of the communications industry who might not have had the opportunity to attend. A common malady The presentation revolved around a case study of an Experian client. Like many communications industry companies, this client had multiple acquisition systems in place to process consumer and commercial applications. In addition, many of the processes to mitigate fraud and support Red Flag compliance were handled manually. These issues increased both complexity and cost, and limited the client’s ability to holistically manage its customer base. The road to recovery At the beginning of the presentation, we provided a handout that listed the top ten critical functionalities for decisioning platforms. After a thorough review of the client’s system, it was clear that they had none of the ten functionalities. Three main requirements for the new decisioning platform were identified: A single system to support their application processes (integration) A minimum of 90% automatic decisions for all applications (waterfall) The ability to integrate into various data sources and not be resource intensive on their IT department (data access) Decisioning as a ServiceSM is a custom integrated solution that is easily applied to any type of business and can be implemented to either augment or completely overhaul an organization’s current decisioning platforms. We designed this client’s solution with a single interface that manages both consumer and commercial transactions, and supports a variety of access channels and treatment strategies. Following implementation, the client immediately benefited from: Streamlined account opening processes A reduction in manual processes Decreased demand on IT resources The ability to make better, more consistent decisions at a lower cost The agility to quickly respond to changing market needs and regulatory challenges Evaluate your own business Do you recognize some of your own challenges in this post? Download our checklist of the top ten critical functionalities for decisioning platforms and evaluate your own system. As you go through the list, think about what benefits you would derive by having access to each of the capabilities. And if you’d like to learn more about Decisioning as a Service, please complete our form.
By: Kennis Wong Data is the very core of fraud detection. We are constantly seeking new and mining existing data sources that give us more insights into consumers’ fraud and identity theft risk. Here is a way to categorize the various data sources. Account level - When organizations detect fraud, naturally they leverage the data in-house. This type of data is usually from the individual account activities such as transactions, payments, locations or types of purchases, etc. For example, if there’s a purchase $5000 at a dry cleaner, the transaction itself is suspicious enough to raise a red flag. Customer level - Most of the times we want to see a bigger picture than only at the account level. If the customer also has other accounts with the organization, we want to see the status of those accounts as well. It’s not only important from a fraud detection perspective, but it’s also important from a customer relationship management perspective. Consumer level - As Experian Decision Analytics’ clients can attest, sometimes it’s not sufficient to look only at the data within an organization but also to look at all the financial relationships of the consumer. For example, in the situation of bust out fraud or first-party fraud, if you only look at the individual account, it wouldn’t be clear whether a consumer has truly committed the fraud. But when you look at the behavior of all the financial relationships, then the picture becomes clear. Identity level - Fraud detection can go into the identity level. What I mean is that we can tie a consumer’s individual identity elements with those of other consumers to discover hidden inconsistencies and relationships. For example, we can observe the use of the same SSN across different applications and see if the phones or addresses are the same. In the account management environment, when detecting existing account fraud or account takeover, this level of linkage is very useful as more data becomes available after the account is open. Loading...